Quick Answer
A readiness self-assessment is an evaluation you run yourself to measure where your organisation stands against a standard or regulation before certification or testing. The Cloudsphere Readiness Check offers ten free yes/no questionnaires with no account needed: ISO 27001 (36 questions), the PDP Law, BCM, risk management, internal audit (16 each), NIST CSF-based cyber security maturity (24), and pentest readiness for web, network, cloud, and IoT (14 to 15). Each takes about 6 to 10 minutes; your score, readiness level, and improvement priorities appear instantly, with a PDF report sent by email.
How Far Are We From What Is Being Asked?
Most organisations start thinking about ISO 27001 or penetration testing because of an outside trigger: a tender that requires a certificate, a corporate client sending a security questionnaire, or Indonesia's Personal Data Protection (PDP) Law obligations starting to come up. The first question is almost always the same: how far are we from what is being asked?
Answering it by guesswork is expensive. Budgets come out too small because there are more gaps than expected, or too large because some controls were already running. A pentest ordered before the system is ready also tends to produce basic findings the team could have fixed on its own first.
Self-assessment is the cheapest way to get that first picture. This article explains how it works, how to read the results, and where its limits are, using the Cloudsphere Readiness Check as the example: ten free questionnaires you can complete without creating an account.
In short
The Readiness Check has ten yes/no questionnaires covering ISO 27001, the PDP Law, BCM, risk management, internal audit, cyber security maturity, and pentest readiness by domain. Each takes about 6 to 10 minutes. Your score, readiness level, and improvement priorities appear instantly, then arrive in your inbox with a link to a PDF report.
What a Readiness Self-Assessment Is
A readiness self-assessment is an evaluation you run yourself. The organisation answers a set of questions about the controls it already operates, and those answers are compared against the requirements of a standard or regulation. The result is not a pass or fail verdict. It is a map: which areas are strong, which do not exist yet, and which to tackle first.
In the Cloudsphere Readiness Check, every question is answered yes or no. The score is the percentage of yes answers, and every no carries one short recommendation that points to a concrete step, such as a clause to meet or a document to write.
Free, no account
Just your company name, scope, name, and business email. No sign-up, and no obligation to use any service.
Instant results
Score, level, per-area breakdown, and recommendations appear as soon as you finish. You do not have to wait for anyone to contact you.
PDF report
The report contains an executive summary, per-area scores, an improvement plan, and an appendix of your answers. The link is emailed to you and stays valid for 90 days.
Grounded in current standards
ISO/IEC 27001:2022, ISO 22301, ISO 31000, the IIA's Global Internal Audit Standards, the NIST Cybersecurity Framework, Law No. 27 of 2022, and OWASP, PTES, and CIS Benchmark practice for technical testing.
Ten Questionnaires: Choose by What Triggered the Question
The questionnaires sit in four categories: compliance and governance, risk management and internal audit, cyber security maturity, and technical security testing. Choose the one that matches the question you are facing, not the one that sounds most complete.
Not sure which to choose?
Start with Cyber Security Maturity. Its twenty-four questions span all six NIST CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), so the result shows which areas deserve a closer look with a more specific questionnaire.
| Questionnaire | Reference | Questions | A fit if you |
|---|---|---|---|
| ISO 27001 | ISO/IEC 27001:2022, clauses 4 to 10 and Annex A | 36 | Are preparing for certification, or need a certificate for a tender |
| PDP Law | Law No. 27 of 2022 | 16 | Process customer or employee personal data |
| BCM | ISO 22301 | 16 | Need to show business continuity readiness |
| Risk Management | ISO 31000 | 16 | Are building or tidying an enterprise risk framework |
| Internal Audit | Global Internal Audit Standards (IIA) | 16 | Want to assess the maturity of the internal audit function |
| Cyber Security Maturity | NIST CSF, six functions | 24 | Do not know where to start |
| Web Application Pentest | OWASP | 15 | Will test a web application or API |
| Network Pentest | PTES and NIST | 15 | Will test an external or internal network |
| Cloud Pentest | Configuration and IAM on AWS, GCP, Azure | 15 | Will test a cloud environment |
| IoT Device Pentest | OWASP IoT Top 10 | 14 | Will test IoT or OT devices |
How It Works
Answer honestly, not optimistically
A self-assessment is only as accurate as its answers. If a control runs only partly or has no evidence yet, answer no. A lower but honest score is far more useful for budgeting than a high score that collapses at audit.
Choose a questionnaire
Open the Readiness Check page and pick one of the ten questionnaires. Each card shows the number of questions and the areas covered.
Fill in four short fields
Company name, planned scope, your name, and business email. The scope lets the results be read in the right context, for example the whole organisation or a single digital service.
Answer yes or no, area by area
Questions are grouped by area, such as by clause for ISO 27001 or by NIST CSF function for cyber security maturity. Answer according to what actually runs today and can be evidenced.
Get your results and report
Score, readiness level, per-area breakdown, and improvement priorities appear instantly. A summary and a link to the PDF report are emailed to you.
How to Read the Score and Readiness Level
The score is the percentage of yes answers across all questions. It then maps to one of three levels. Level names vary by questionnaire, but the thresholds are the same everywhere:
| Score | ISO 27001 level | Pentest level | What it usually means |
|---|---|---|---|
| 0–39% | Foundation Stage | Not Test-ready | The foundation is not in place. For ISO 27001, prioritise clauses 4 to 6 (context, policy, risk assessment, SoA) before technical controls. |
| 40–74% | Developing | Partially Ready | Most elements exist, but the remaining gaps would become audit findings or blur the test results. |
| 75–100% | Certification-ready | Test-ready | Close to ready. Next come the internal audit and management review, or agreeing the pentest scope and schedule. |
Per-Area Breakdown and Improvement Priorities
Beyond the total score, look at two other parts of the results page. The per-area breakdown shows where the score is held back: one empty mandatory clause is more urgent than several incomplete Annex A controls, even when the total score is the same.
Improvement priorities list up to six recommendations drawn from your no answers, in the questionnaire's area order. In the ISO 27001 questionnaire, mandatory clauses 4 to 10 come before Annex A controls, so the list works as a first order of work.
After the Results: Next Steps
Self-assessment results are most useful when they turn straight into a plan. These are the steps that usually make sense for each score range:
Score below 40%
Build the foundation first: an information security policy, a risk assessment, and clear ownership. A structured gap analysis helps set a realistic order of work and budget.
Score 40–74%
Close the gaps shown in your improvement priorities and complete the evidence, then verify with a gap analysis before scheduling a certification audit or pentest.
Score 75% and above
Prove those answers: a gap analysis that reviews documents and evidence of implementation, or a penetration test to confirm technical readiness.
What It Costs to Go Further
The Readiness Check costs nothing, and neither does the initial consultation to discuss your results. If you decide to continue with Cloudsphere, ISO 27001 consulting ranges from IDR 25 to 40 million for a single-site organisation, from gap analysis through certification audit support. Certification body audit fees are not included; the client pays them directly to the certification body.
Penetration testing starts at IDR 15 million for a single small-scale web application, including the technical report, executive summary, and one verification retest. Final pricing for both follows the agreed scope.
What Self-Assessment Cannot Replace
Self-assessment is a starting point, not a substitute for formal evaluation. Knowing the difference keeps the results in their proper place.
A high score is not a certificate
A score of 75% or more means the requirements you assessed yourself are largely met. It does not guarantee passing a certification audit, because auditors assess evidence, not answers. Use the score as a planning tool.
Self-assessment (Readiness Check)
- Based on your own answers
- Done in about 6 to 10 minutes
- Free, with no obligation
- Gives a first picture and an order of priorities
- Does not examine documents or evidence of implementation
Formal gap analysis or pentest
- Performed by an independent consultant or tester
- Reviews documents, interviews, and evidence of implementation
- Produces findings that can be defended
- Forms the basis of an implementation plan and budget
- A pentest tests the system directly, not questionnaire answers
Conclusion
Before you build a certification budget or order a pentest, ten minutes spent measuring where your organisation stands is almost always worth it. The results give you concrete material for discussions with management, with consultants, and with your own technical team.
Start with the questionnaire closest to your trigger: the ISO 27001 Readiness Check for certification, the PDP Law Compliance Check for personal data, or the Web Application Pentest Readiness Check before testing. If you do not know where to start, the Cyber Security Maturity Check gives a complete picture based on the NIST CSF.
To understand what comes next, read the ISO 27001 certification guide and its cost breakdown, or the penetration testing price guide for Indonesia.
The Readiness Check is free, needs no account, and shows results instantly. Once you have your score, our consultants can help you read it and plan the next step, from gap analysis through audit support or testing.
Frequently Asked Questions
What is the Cloudsphere Readiness Check?
The Readiness Check is a set of ten free yes/no questionnaires from Cloudsphere that measure an Indonesian organisation's readiness for ISO 27001, the PDP Law, BCM (ISO 22301), risk management (ISO 31000), internal audit (IIA standards), cyber security maturity (NIST CSF), and penetration testing of web applications, networks, cloud, and IoT devices. Results appear instantly with no account required.
Is Cloudsphere's ISO 27001 self-assessment free?
Yes. Every Readiness Check questionnaire is free, needs no account, and does not commit you to any service. You only provide your company name, scope, name, and business email. The initial consultation to discuss your results is also free of charge.
How long does a readiness questionnaire take?
About 6 to 10 minutes, depending on the questionnaire. The pentest questionnaires per domain have 14 to 15 questions; the PDP Law, BCM, risk management, and internal audit questionnaires have 16 each; cyber security maturity has 24; and ISO 27001 has 36 questions covering clauses 4 to 10 and Annex A.
How do I read my Readiness Check score?
The score is the percentage of yes answers. A score of 0 to 39% means the foundation is not in place, 40 to 74% means most elements exist but the remaining gaps would still become audit findings, and 75% or more means you are close to certification or test readiness. The results page also shows a per-area breakdown and up to six improvement priorities.
Is a self-assessment the same as a gap analysis?
No. A self-assessment is a first picture based on your own answers and does not examine documents or evidence of implementation. A formal gap analysis is carried out by a consultant who reviews documents, interviews staff, and checks evidence directly, so its findings can underpin an implementation plan and budget.
What does it cost to continue to ISO 27001 consulting or a pentest after the self-assessment?
Cloudsphere's ISO 27001 consulting ranges from IDR 25 to 40 million for a single-site organisation, excluding the certification body's audit fee, which the client pays directly to that body. Penetration testing starts at IDR 15 million for a single small-scale web application, including the report and one retest. Final pricing follows the agreed scope.
Related Templates & Checklists
Supporting material to act on what this article covers. Free — one email, once.
ISO 27001 Gap Assessment Checklist
Measure your organization's readiness against ISO 27001:2022 and find gaps before certification.
Download freePenetration Test Preparation Checklist
Prepare for a pentest the right way: asset scoping, test accounts, testing windows, PICs, and legal aspects — so testing runs smoothly from day one.
Download freePDP Law Compliance Checklist
A compliance checklist against Law No. 27 of 2022 on Personal Data Protection (PDP Law).
Download freeAbout the Author
Cloudsphere Consulting Team
GRC & Security Assessment
Cloudsphere's GRC consulting team, guiding Indonesian organizations to ISO 27001 certification and PDP Law compliance from gap analysis through audit.
Share Article
Related Topics
Related Articles
SNI ISO 27001
SNI ISO/IEC 27001 vs ISO/IEC 27001: What's Different, and Which Certification Body to Choose
August 25, 2026
ISO 27001 Tender
ISO 27001 as a Tender Requirement: How to Count Backwards From the Deadline
August 25, 2026
GRC Software
GRC Software in Indonesia: Must-Have Features, Options Compared, and Pricing (2026)
August 15, 2026